PT-2026-79333 · Apache · Cloudstack
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache CloudStack version 4.20.3.0
Apache CloudStack version 4.22.1.0
Description
Certificate validation failures in SAML authentication allow a malicious agent to forge a SAML response to the management server. To exploit this, an attacker must spoof the IP address of the Identity Provider (IdP) or register a URL of their choice in the management server, enabling unauthorized login using forged signatures.
Recommendations
Upgrade version 4.20.3.0 to 4.20.3.1 or above.
Upgrade version 4.22.1.0 to 4.22.1.1 or above.
Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloudstack